CipherLayer
Home / Tools / SHA Hasher

SHA Family Hasher

SHA-1, SHA-256, SHA-384, SHA-512 hashing in your browser via Web Crypto. Includes an avalanche effect demo, hash chain visualization, and HMAC-compatible output formatting.

Avalanche demo Hash chain HMAC format Web Crypto API Zero network

Inputs

If "treat as hex" is checked, input is parsed as raw bytes. Otherwise UTF-8 text.

Output

// Hash output will appear here SHA hashes are one-way: you cannot reverse them to recover the input. They are also deterministic: same input → same output, every time, on any machine.
Algorithm
—
Output length
—
Time
—
Hash ≠ encryption. A hash is one-way. There is no key, no decryption. If you need to recover the input, you need encryption (use our AES-GCM tool). If you only need to verify integrity or fingerprint data, hashing is correct.

Why this tool, and why this version

Every developer eventually needs a hash function and reaches for an online tool. Most of them are correct but minimal: paste text, get hex. That tells you nothing about what a hash function is supposed to do. This tool is designed to show you the properties that make a cryptographic hash cryptographic.

The avalanche effect tab demonstrates that flipping one bit in the input changes about half of the output bits. This is not a nice-to-have; it's the central security property. Without it, similar inputs would produce similar hashes, and an attacker could correlate plaintexts by their digests. SHA-256's avalanche behavior is so consistent that you can predict the bit-difference count within a few percentage points.

The hash chain tab shows what happens when you feed the output back as input. Each iteration looks unrelated to the previous input — yet it is fully deterministic. This is how Bitcoin mining works: miners increment a nonce, hash it, hash again, and search for a result that starts with N zeros. The chain tab lets you see in 5-10 iterations what miners do billions of times per second.

All hashing is done via the Web Crypto API — the same primitive your browser uses for TLS, certificate fingerprints, and Subresource Integrity tags. The implementation is the OS-native one (typically OpenSSL or BoringSSL), not a JavaScript re-implementation.

Who this is for

Engineers validating integrity

You download a file and the publisher lists its SHA-256. This tool lets you compute the same hash on your end without uploading the file anywhere. It's the same workflow as shasum -a 256 file but stays in the browser.

Students studying hash properties

Avalanche, collision resistance, preimage resistance — these are abstract until you see them. The avalanche demo turns the abstract into numbers you can measure.

Cryptocurrency & blockchain developers

Block headers, transaction IDs, Merkle nodes — all are double-SHA256 in Bitcoin, single-SHA256 in Ethereum. Visualize what your chain is actually computing.

Frequently asked questions

Is SHA-1 broken? ▶
Yes, for collision resistance. In 2017, Google and CWI Amsterdam produced two different PDF files with the same SHA-1 hash (the SHAttered attack, ~$110k compute). This means SHA-1 cannot be trusted for digital signatures or certificate fingerprints. SHA-1 is still safe for some non-collision uses (e.g., HMAC-SHA1), but you should default to SHA-256 or SHA-512. This tool offers SHA-1 for legacy compatibility and educational comparison only.
What's the difference between SHA-256 and SHA-3? ▶
SHA-256 is part of the SHA-2 family designed by the NSA, based on the Merkle–Damgård construction. SHA-3 (Keccak) won a public NIST competition in 2012 and uses a sponge construction — completely different internal design. For most purposes, both are secure and interchangeable. SHA-3 has theoretical advantages if SHA-2's design assumptions are ever broken. Web Crypto now supports SHA-3 in modern browsers, but SHA-256 remains the dominant choice for compatibility.
Can hashes be reversed? ▶
No — not in the cryptographic sense. SHA-256 is a one-way function: given the hash, you cannot recover the input. What attackers do instead is brute-force: try millions of candidate inputs and see which one matches. For short or predictable inputs (a 4-digit PIN, the word "password"), brute force is trivial. For high-entropy inputs (32 random bytes), brute force is computationally infeasible — there are 2²⁵⁶ candidates. Hashing is reversible only against weak inputs.
Why does changing one character change the entire hash? ▶
That's the avalanche effect, and it's intentional. SHA-256 mixes each input bit with every other input bit through 64 rounds of compression. After the first round, half the state depends on the changed bit. After round 2, three-quarters depend on it. By round 64, the dependency is total. This is what makes the output look random and prevents attackers from finding relationships between similar inputs.
What does "treat as hex" mean? ▶
By default, your input is interpreted as UTF-8 text. With "treat as hex" enabled, the input string is parsed as pairs of hex digits (00-FF) and those become the raw bytes that get hashed. This is useful when you have a binary key in hex format and need its hash. Example: the bytes 0xDE 0xAD 0xBE 0xEF would be entered as deadbeef.
What are hashes used for in practice? ▶
Four major uses: (1) Integrity verification — Git uses SHA-1 to detect file changes; downloaded software publishes hashes for tamper detection. (2) Digital signatures — instead of signing a large file, you sign its hash. (3) Password storage — store hash(password), not password (use a slow KDF like bcrypt for this; see PBKDF2). (4) Proof-of-work — Bitcoin miners search for inputs whose hash starts with N zeros.
Why is there an "HMAC format" option? ▶
It's a learning aid. Naive h = hash(key || message) was used in early protocols and has known attacks (length-extension). The display shows this formulation explicitly so you can compare it to proper HMAC construction (h = hash((key ⊕ opad) || hash((key ⊕ ipad) || message))). If you actually want HMAC, use our HMAC tool — it implements the construction correctly.

Limitations you should know